Delete option coming in child System

We have recently implemented CUA in our landscape.Now that we are able to see delete option available in one of the child system which is not there in the initial stages and not in any othere child systems.Can any one help me in finding the reason for its occurance and make it consistent with other systems.

Hi Naveen,
Do one thing. Try to save the CUA model through SCUA once again and look out for errors. Let yus know the errors you get. Also do one thing. Try remote login from the master ssytem into child system using the RFC destination. I think the ALE user in the RFC destination is either locked or has wrong password maintained.
regards.
Ruchit.

Similar Messages

  • How to delete users in the child systems with CUA?

    Hi All,
    We have:
    1.  My SAP ERP 2005  (ECC 6.0)+ Windows 64bit + Oracle 10
    2. EP 7.0 + Windows 64bit + Oracle 10
    3. BI 7.0 + Windows 64bit + Oracle 10
    4. Solution Manager 4.0 (CUA)
    We managed all our QA and DEV users in ECC, EP using CUA from the Solution Manager server (Productive servers  and all the BI  7.0 System Landscape aren't in the CUA).
    My problem is when i want to delete a user. Sometimes if you delete a user in the solution manager (where the CUA is defined) the user still  exists in the Child Systems. In fact you can  see it with the SU01 only in the child system. I guess the idea is that if you delete the user in the CUA them  the user is delete in the child system.
    I found this information in the SAP Help:
    As well as the authorizations already mentioned, you also need another authorization in the central system for object S_USER_SYS. You can only assign new systems to a new user with this authorization. ( No Problem with this )
    When a user is deleted in the central system, the system entry for the user is retained until the deletion is confirmed. If an error occurs, you can repeat the deletion by canceling the system (in the child system).
    What does mean: deletion is confirmed? 
    Best Regards,
    Erick Ilarraza

    Hi, thanks a lot for your reply.
    We used the SAP Transaction SCUG to solve CUA Problem.
    It is something about the refresh of the user in the Parent / Child systems, you need to Re-Refresh users and delete it again.
    Best Regrads,
    Erick Ilarraza

  • CUA- Deleting user IDs from Child systems

    Is there a possibility of configuring CUA in such a way that user IDs can be created and access can be updated from CUA but deleting user IDs should be taking place only in the child system (Not in all the child systems)?

    Generally good advice to keep the uniqueness of UIDs over time, also after Elvis has left the building
    What you could consider is a CUA RFC user which is not authorized to delete UID's and schedule a purge job for those IDOCs which deleted only them.
    However these sorts of "workaround" solutions are not the best advise, to be honest. What happens it someone temporarily assigns SAP_ALL because there is a big problem and authorizations should be excluded as the cause to get it working again?
    Also, every time a new child system is added to the CUA you will be flooded.
    My advice: Rather change your procedure (as discribed by Jurgen).
    What would be interesting to test is whether you are authorized to move a user (change the authorization relevevant group which they currently have) to a group which the CUA user is no long able to subsequently administrate? But theen you will still be hunting down IDOCs from time to time, most likely.
    If your shop is big enough to have these systems you have described, then you might want to consider an IdM system to replace your CUA at some time.
    If you wish, I will move this thread to the IdM forum.
    Cheers,
    Julius
    ps: Please do not cross-post.

  • CUP:Deletion of account in CUA child system leaves system assignment in CUA

    Hello all CUP experts,
    I face a problem with CUA connected systems, more precisely in the account deletion process. The account is deleted in the CUA child system, but it leaves the system assignment in the CUA system.
    Is there a way to get CUP to delete also the CUA system assignment, which I understand has to happen before the child system account deletion?
    Br,
    Stefan Ericsson
    +358-50-4867527

    Hi Naveen,
    1. I have synchronized the company address in central system to all the child systems.
    2. This particular child system has an additional company address "XYZ" (which is causing the problem). This address is not being copied to the central system from transaction SCUG. It throws an error saying that the address is incorrect (Missing Country Information). So, when I want to edit the address to get this thing fixed, in the child system, it won't let me do that. I can neither edit it nor delete it. I get the error messages as I have posted earlier.
    So I have changed the company address of all the users who were using address "XYZ" to a different address so that I can delete the company address "XYZ". But, I am still not able to delete the address.
    If you could guide me on how can we edit or delete the company addresses in a  child system (other than from Transaction SUCOMP), it would be great.
    Thank You for your time on this thread.
    Any input I will appreciate.
    Jaya

  • CUA -Unlock Users in Child System

    Hi,
    I am in the process of configuring CUA
    I have a central system ABC and Child system XYZ
    I have a user TEST. I wanted to Lock only the user TEST from the Central System. Please let me know of what configuration i have ton setup in SCUM to achive the same
    I am able to go a Global Unlock and Global Lock , which will unlock/lock the user TEST in all the Systems 
    Please guide

    Hi,
    Your present configuration is as needed for you.
    You have selected the option "in the child system with automatic redistribution to the central system and the other CUA child systems" which is as you need.
    Regards,
    Pavan

  • CUA and SU10: unexpected deletion in all child systems

    Hi,
    I am facing with a problem with SU10 and CUA.
    I have updated a lot of users with SU10 in CUA. For 20 users in a child system, I first add a new role, everything is fine. Then I perform a remove of a old role (I know that the end date will be changed), everything is fine except for one user. All roles were removed from all systems where the user is defined ! However, when I look in each child systems, it is not the case, the roles are well present except in the child sytem for which I do the remove.
    This problem occurs twice, for different users. It is a real problem because we have to adapt a lot of users.
    I have reinstalled the 'missing' roles with SCUG and with the change document for users but it can be a workaround because I have discovered this by chance. I can imagine check all users after each run of SU10.
    Hope someone can help me.
    Regards

    Hi Olivier,
    that sounds like you are facing the problem corrected with sap note #1117530......
    The removal shows up only at the next change of a user, the actual deletion of role assignements because of the copy might have happend already some time ago.....
    b.rgds, Bernhard

  • Id deleted in child system

    Hi Gurus
    A user id has been deleted in cua child system . Is there any way to trace who deleted the user id ?
    Change document shows its deleted by CUA_ADMIN , but we cant trace the original id with which the user has been deleted . Please help!!!!!

    You have to check it in the CUA (domain) not in the chid system..... always in the child system is going to appear the RFC user used to distribute the changes from CUA.
    SU01 - enter user - Go to >Information>Change documents for users
    Regards,
    Marco

  • Deletion doent reflect child system

    Hi All,
    We have deleted a composite role from CUA,but to our suprise single role still exist in child system. How to delete these now?
    We have tried to re-distrubute the idoc- unsuccessful
    We cant use PRGN_COMPRESS_TIMES  as CUA is conneted.
    Any help will be appreciated.
    Thank you,
    Sri

    Hi,
    What is the status of the Idocs in Central system and Child systems? Are they processed properly? If yes and still you see the Single Roles in the child system then do the following:
    1. Check the Composite role first in the child system (and in central also if it is existing there too). If the role is not ok to see then first take of it.
    2. Do a text comparison in the Central system for the Respective Child system(s) and save the user once more by getting into change mode.  Now check whether the roles are gone or not.
    3. if the single roles are still there then assign the composite role once more and save and then remove it again. Check the SCUL status for the user id and process it if not processed already.
    4. process the IDocs manually in BD87 if not processed in the central and / or Child system(s).
    Let us know how it goes.
    regards,
    Dipanjan

  • Users were re-created in Child systems not in Cnetral System (CUA)

    Hi,
    The set of users were deleted some time back and today i verified in child system (PROD) with criteria as list of users without roles/profiles then I found a set of users in child systems.
    Were as those user master records are not showing in Central System (CUA).
    I verified the change document, It is showing the deleted date and later some time again it was created with no roles and profiles. On the same date all the others users are also get created.
    Then I have checked the change document of a user and verified is there any IDOC was generated in central system on that time and date but I didnu2019t find anything...
    I was expecting that the old IDOC's which are in status "distribution unconfirmed" with of the user and later there would be happen many changes for that user and which are get reflected in child system but the IDOC which was in unconfirmed status. When any one try's to execute the process through BDM2 or BD87 for that IDOC then again there would be chance of re-build the user account..... But one thing i was confused is if the old IDOC get re-generate then it has to be shown in the CUA system also?.
    It was strange issue, so please let me know what the reason behind it.....
    Please help me out...
    SV

    >
    Nishant Sourabh wrote:
    > I assume BD87 was executed in the child system and the idocs where manually processed which created these ids back again ....not sure if that is what happened. never seen something like that.
    Hi Nishant,
    what you are writing is the most common situation of how these users got 'recreated'.
    If you have a look at the method for user change idocs, you will notice, that it is the same method for creation and changing (CLONE).
    So if you have an unprocessed change idoc in the child system and you delete the user (succesfully) and reprocess this idoc in the child system locally, the user will get 'recreated'.
    b.rgds,
    Bernhard

  • I downloaded photos from a camera and cannot delete the ones I want as it displays only move and slideshow options but no trashcan or delete options

    I downloaded photos from digital camera and now I want to delete some but when I hit the photos icon it only brings up pics with the only options being move or slideshow no trashcan or delete options available

    You should be able to delete photos taken with the iPad, copied onto it via the camera connection kit, or saved from emails/websites etc directly on the iPad - either via the trashcan icon in the top right corner if viewing the photo in full screen, or via the icon of the box with the arrow coming out of it in thumbnail view.
    Photos that were synced from your computer are deleted by moving/removing/de-selecting them from where they were synced from and then re-syncing

  • How to find who has deleted the query in Production system

    I Experts,
    I have an issue. Someone has deleted one query in Production system.
    How can i find who has deleted the query??
    I searched the ans for the same i the below threads :-
    Query deleted in production
    How to find out who has deleted the production Query
    But it didn't help me as i couldn't understand how to use the transaction SLG1.. Can Someone please explain me how can i find out who has deleted the Query..
    Regards,
    Pavan Raj

    Hello,
    Please, remember the date on which date the query has seen last time  in the production server. You can use the last date in the From date and To date would be current  date and execute the SLG1 tcode. It would list you all the logs in the Object text you can search for BEX Query designer and sub object text column you can check for delete logs options.
    Double click on the object will list you the query and name. From the user column you can find who has deleted the query.
    Might be this can help you for analysis.
    Thanks
    Geeta Sharma

  • CUA Roles residing in Child system are not showing in Central System

    I just hooked up CUA today and have linked 8 child systems to the central system.  The 8 child system users and roles have already been established in the child systems.  Do I need to run program susr_zbv_get_receiver_profiles in each of the child systems to get the roles in the child systems to show up in the Central System for each user?  I tried this in one child system and it worked.
    Or is there something else I need to do without going into each child system?
    I tried this program susr_zbv_get_receiver_profiles in the Central system but it did not work.

    are you looking for roles or profiles? profiles will not show up in the central system. If you run SCUL do you see anything? when you first added the child system did you use an SAP user that had the proper permissions? In both the child and the parent? There are two roles that the user must belong to to add the child to the parent they are SAP_BC_USR_CUA_SETUP_CENTRAL and SAP_BC_USR_CUA_CENTRAL.
    If you have any question about the permissions of these user at the time you added the child to the parent I'd delete the child and re-add with either the above roles or a user with SAP_ALL in BOTH the child and the parent systems

  • Canwe reduce the data size in XI coming from source system

    Hi Experts,
    Happy new year 2010!!!
    Is there any option to reduce the size of the messages in XI coming from Sorce system??
    suppose the size of the sorce message is 5 MB, can we reduce this size in XI. Any option for this please to improve system performance.
    Many Than

    Actually, upto 5MB is the ideal size of message that should pass through XI. Still, the solution for your problem depends upon the type of adapter in use. e.g. if it is flat file, you may use Recordset per message, or you may use PayloadZipBean in module chain for adapters supporting modules at sender.
    Regards,
    Prateek

  • Role assignment to user in child system

    Hi,
    We have a CUA with role assignment in SCUM defined as global. There is any way of assigning roles to users in child system when CUA system is not available? There is any way to allow roles assignement  in both Parent and  child systems?
    Many thanks for your help!!
    Raquel

    One way would be to temporarily delete the CUA assignment in the child and then maintain locally, but you will need to attach it again... and decide whether you want the CUA master to know about what you have done.
    Plan B on older Support Packs is to take a look at the correction instructions of [SAP Note 1504495|https://service.sap.com/sap/support/notes/1504495] but for this you need full access () to the S_USER objects, in which case you could detatch the CUA anyway.
    However as a temporary workaround in Test systems it could have been usefull.
    Plan C: Allow reference user assignments locally and authorize the role indirectly. Via the available authorizations of and access to the reference users you can then contain the scenario. Works fine for me if the concept of reference users is understood.
    However in most cases you should do it via the CUA and will end up doing this anyway via the CUA - that is what you have a CUA for. So... logon to your CUA in the morning, give the SAPGui scheme a nice bright colour and administrate the users and role assignments there. This is a small price to pay compared to not having a CUA or IdM...
    Cheers,
    Julius

  • User roles un-assigned in CUA but acces in child system is ok

    hi
    i am have a really weird issue. a user who has access in roles in child clients, suddenly his roles disappeared from CUA. it did not effect access in child systems. any suggestions how to investigate this.
    thanks

    Did you click the Naughty Button in SCUL? Check OSS Note 1074552...
    Could also be a cause of failing idocs.
    Regards,
    Trond
    PS: The above note is for cases where users loose their visible role assignments in CUA, although roles remain assigned in the child system(s), not for cases where role assignments from CUA never trickles through to the child systems. The mentioned OSS note is a direct result of a case worked on by yours truly in 2007. I include below a warning I posted on sapfans about the issue:
    Word of warning: RSUSR_CUA_CLEANUP_USZBVSYS is faulty!!!
    The program RSUSR_CUA_CLEANUP_USZBVSYS is available as a standard SAP program from at least version 6.20. It can be run from SE38/SA38 or launched from a pushbutton (far right) on the "results" screen of transaction SCUL.
    The program is intended to delete "obsolete" entries from table USZBVSYS, which contains log entries for assigned child systems in a CUA environment. The program is run in the main CUA system, and supposedly deletes entries for systems where users no longer have access.
    There is a serious problem with the program, as acknowledged and confirmed by SAP in an OSS note I opened a few days ago. Under certain circumstances (more than 500 entries for any child system in the CUA landscape), the program wipes clean the whole table, instead of just the obsolete entries.
    The consequences are dire. Table USZBVSYS is used for several fundamental CUA functions, such as remote password reset from the CUA master system. After the wipe, executing SU01 and attempting to reset a users password in a child system will no longer work. The assigned child systems are no longer visible in the reset password pop-up (nor anywhere else in SU01, including the Roles tab). You'll have to edit the user via SU01, and click on the annoying pop-up showing "new system assigned to user" for each system where the user has access...
    The only way to fix the issue is to re-run SCUG for all systems in the CUA landscape. We had to do this across 6 CUA's, each containing 30+ child systems/clients and 10000+ users, which was very time-consuming and annoying. Also, there seems to be cases where roles have been wiped out from users on the CUA master systems, possibly due to consequences of the empty USZBVSYS table.
    SAP has conceeded the program is faulty, and have proposed a new version (note 1074551). Without applying this correction, the program should NOT be run.
    Note that users can still log in to and work in the child systems, it's just the "visibility" from the CUA master system which is missing. Tables USLA04/USL04 are still intact.
    Just wanted to warn the community; we've spent some considerable time discussing with SAP and rectifying the mess created by RSUSR_CUA_CLEANUP_USZBVSYS...
    Edited by: Trond Stroemme on Aug 5, 2008 3:03 PM

Maybe you are looking for